CVE-2018-6876: ImageMagick

Medium severity, CVSS 6.5. EPSS: 2.5% chance of exploitation in the next 30 days.

The OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, allows remote attackers to cause a denial of service (stack-based buffer under-read) via a crafted bmp image.

Affected products

Published 2018-02-09. Last modified 2026-06-17.